IBM Aspera Faspex Sensitive Information Enumeration Vulnerability

Vulnerability

A vulnerability in IBM Aspera Faspex versions 5.0.0 through 5.0.14.1 allows authenticated users to enumerate sensitive information by exploiting package identifier enumeration. This could lead to the exposure of confidential data.

Impact

Exploitation of this vulnerability could result in the unauthorized enumeration of sensitive information, potentially leading to data exposure.

Remediation

Users are advised to upgrade to IBM Aspera Faspex version 5.0.14.2, available through the IBM Support Fix Central.

Added: Dec 26, 2025, 3:22 PM
Updated: Dec 26, 2025, 3:22 PM

Vulnerability Rating

Custom Algorithm
spread
1.9
impact
2.5
exploitability
4.8
remediation
7.7
relevance
1.7
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.